CVE-2023-36535: Zoom Rooms

Medium severity, CVSS 6.5. EPSS: 1.2% chance of exploitation in the next 30 days.

Client-side enforcement of server-side security in Zoom clients before 5.14.10 may allow an authenticated user to enable information disclosure via network access.

Affected products

  • Zoom Rooms: before 5.14.10 (fixed in 5.14.10)
  • Zoom Virtual Desktop Infrastructure: before 5.14.10 (fixed in 5.14.10)
  • Zoom Zoom: before 5.14.10 (fixed in 5.14.10)

Published 2023-08-08. Last modified 2026-06-17.